# The first AI-run ransomware attack still needed a human

> Security firm Sysdig has documented what it calls the first agentic ransomware campaign, dubbed JadePuffer, in which an AI agent handled the technical labor of an attack: exploiting known flaws in Langflow and MySQL, encrypting more than 1,300 configuration records, and at one point fixing a broken login in 31 seconds while narrating its own reasoning. It is a vivid look at what autonomous offensive tooling actually does when turned loose. The reassuring caveat is in the headline. A human still set up the infrastructure and, crucially, chose the victims. The AI was a very fast technician, not a strategist. For now the hardest, most consequential decisions in an attack remain human ones. The unsettling part is what the researchers infer from the economics. If an agent can carry out the grunt work of an intrusion, the main limit on how many campaigns a crew can run becomes budget rather than skilled labor. That points toward a future where thousands of attacks run in parallel, which is exactly the scaling problem defenders least want to face.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: TechCrunch · Published Sunday, July 19, 2026_

## Wortins' read

Security firm Sysdig has documented what it calls the first agentic ransomware campaign, dubbed JadePuffer, in which an AI agent handled the technical labor of an attack: exploiting known flaws in Langflow and MySQL, encrypting more than 1,300 configuration records, and at one point fixing a broken login in 31 seconds while narrating its own reasoning. It is a vivid look at what autonomous offensive tooling actually does when turned loose. The reassuring caveat is in the headline. A human still set up the infrastructure and, crucially, chose the victims. The AI was a very fast technician, not a strategist. For now the hardest, most consequential decisions in an attack remain human ones. The unsettling part is what the researchers infer from the economics. If an agent can carry out the grunt work of an intrusion, the main limit on how many campaigns a crew can run becomes budget rather than skilled labor. That points toward a future where thousands of attacks run in parallel, which is exactly the scaling problem defenders least want to face.

## Source

[Read the full story at TechCrunch](https://techcrunch.com/2026/07/06/the-first-ai-run-ransomware-attack-still-needed-a-human/)

## Related coverage

- [Suno AI Music Generator Faces Key Summary Judgment Hearing in Copyright Litigation](https://www.wortins.com/story/suno-ai-music-generator-faces-key-summary-judgment-hearing-i-6062f1bb) — [TLDL](https://www.tldl.io/resources/ai-music-generators-suno-udio-2026)
- [Roblox Launches AI-Powered Game Creation Tool for Mobile Creators](https://www.wortins.com/story/roblox-launches-ai-powered-game-creation-tool-for-mobile-cre-6c653585) — [TechCrunch](https://techcrunch.com/2026/07/16/roblox-launches-an-ai-powered-game-creation-feature-in-its-mobile-app/)
- [Scarlett](https://www.wortins.com/story/scarlett-6996176e) — [Product Hunt](https://tryscarlett.ai/)
- [Walden Robotics Launches with $300M to Deploy General-Purpose Robots in Industry](https://www.wortins.com/story/walden-robotics-launches-with-300m-to-deploy-general-purpose-badf858c) — [BusinessWire](https://www.businesswire.com/news/home/20260715089377/en/Walden-Robotics-Launches-with-$300-Million-to-Put-General-Purpose-Robots-to-Work-Today)
- [The New Gatekeepers: Anthropic, Fable 5, and Quiet Institutionalization of Science](https://www.wortins.com/story/the-new-gatekeepers-anthropic-fable-5-and-quiet-institutiona-7aacb131) — [Medium](https://medium.com/@m.alfaro.007/the-new-gatekeepers-anthropic-fable-5-and-the-quiet-institutionalization-of-science-ae879ae062b2)
- [Stanford Letter: 200+ Economists Warn of AI Disruption Larger Than Industrial Revolution](https://www.wortins.com/story/stanford-letter-200-economists-warn-of-ai-disruption-larger--61b57833) — [Intellectia](https://intellectia.ai/blog/ai-infrastructure-investment-july-2026)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
